Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareWinnti for Windows | Winnti for Windows has the ability to encrypt and compress its payload. |
| T1027.015 Compression |
MalwareWinnti for Windows | Winnti for Windows has the ability to encrypt and compress its payload. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareWinnti for Windows | A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name. |
| T1057 Process Discovery |
MalwareWinnti for Windows | Winnti for Windows can check if the explorer.exe process is responsible for calling its install function. |
| T1070.004 File Deletion |
MalwareWinnti for Windows | Winnti for Windows can delete the DLLs for its various components from a compromised host. |
| T1070.006 Timestomp |
MalwareWinnti for Windows | Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe. |
| T1071.001 Web Protocols |
MalwareWinnti for Windows | Winnti for Windows has the ability to use encapsulated HTTP/S in C2 communications. |
| T1082 System Information Discovery |
MalwareWinnti for Windows | Winnti for Windows can determine if the OS on a compromised host is newer than Windows XP. |
| T1083 File and Directory Discovery |
MalwareWinnti for Windows | Winnti for Windows can check for the presence of specific files prior to moving to the next phase of execution. |
| T1090.001 Internal Proxy |
MalwareWinnti for Windows | The Winnti for Windows HTTP/S C2 mode can make use of a local proxy. |
| T1090.002 External Proxy |
MalwareWinnti for Windows | The Winnti for Windows HTTP/S C2 mode can make use of an external proxy. |
| T1095 Non-Application Layer Protocol |
MalwareWinnti for Windows | Winnti for Windows can communicate using custom TCP. |
| T1105 Ingress Tool Transfer |
MalwareWinnti for Windows | The Winnti for Windows dropper can place malicious payloads on targeted systems. |
| T1106 Native API |
MalwareWinnti for Windows | Winnti for Windows can use Native API to create a new process and to start services. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWinnti for Windows | The Winnti for Windows dropper can decrypt and decompresses a data blob. |
| T1218.011 Rundll32 |
MalwareWinnti for Windows | The Winnti for Windows installer loads a DLL using rundll32. |
| T1480.001 Environmental Keying |
MalwareWinnti for Windows | The Winnti for Windows dropper component can verify the existence of a single command line parameter and either terminate if it is not found or later use it as a decryption key. |
| T1543.003 Windows Service |
MalwareWinnti for Windows | Winnti for Windows sets its DLL file as a new service in the Registry to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareWinnti for Windows | Winnti for Windows can add a service named |
| T1548.002 Bypass User Account Control |
MalwareWinnti for Windows | Winnti for Windows can use a variant of the sysprep UAC bypass. |
| T1569.002 Service Execution |
MalwareWinnti for Windows | Winnti for Windows can run as a service using svchost.exe. |
| T1573.001 Symmetric Cryptography |
MalwareWinnti for Windows | Winnti for Windows can XOR encrypt C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.